- Rick Strafy
- Nette Blogger | 52
Last edited by Rick Strafy (2022-09-29 17:45)
- Marek Bartoš
- Nette Blogger | 823
Escaping should be always done on output, not on input, because it is
I guess you could dig deeper into Latte and use only its escaping functions, but I would ask why don't just use the whole Latte.
Some basic input sanitization is done by RequestFactory in nette/http